Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v4qx-h7r5-6qc8

Опубликовано: 29 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

A process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < 128.10.

A process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < 128.10.

EPSS

Процентиль: 17%
0.00053
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-653

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 2 месяцев назад

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 8.3
redhat
около 2 месяцев назад

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 9.1
nvd
около 2 месяцев назад

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 9.1
debian
около 2 месяцев назад

A process isolation vulnerability in Thunderbird stemmed from improper ...

CVSS3: 9.1
redos
3 дня назад

Множественные уязвимости firefox

EPSS

Процентиль: 17%
0.00053
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-653